registration-form

1 article
sort: new top best
clear filter
0 6/10

A bug bounty hunter discovered LDAP injection vulnerability while testing for blind XSS on a registration form; the application was vulnerable to LDAP injection despite having a .NET WAF in place, with the error message revealing LDAP directory pathname errors that enabled exploitation.

XSS Hunter The WebApplication Hacker's Handbook Davide Tampellini
nc-lp.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details